New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 834856 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Aug 31
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: Lifecycle().StateAllowsTreeMutations() in document.cc

Project Member Reported by ClusterFuzz, Apr 19 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5377103391096832

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_msan_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  Lifecycle().StateAllowsTreeMutations() in document.cc
  blink::Document::UpdateStyleAndLayoutTreeIgnorePendingStylesheets
  blink::Document::UpdateStyleAndLayoutIgnorePendingStylesheetsForNode
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=535692:535694

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5377103391096832

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 19 2018

Components: Blink>DOM
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Components: -Blink>DOM Blink>Paint
Labels: M-66 Test-Predator-Wrong
Owner: xidac...@chromium.org
Status: Assigned (was: Untriaged)
This issue looks similar to  bug 825632 , hence assigning to the same owner for more updates on this issue.

xidachen@ Could you please take a look in to this issue?

Thanks!
Project Member

Comment 3 by ClusterFuzz, May 16 2018

ClusterFuzz has detected this issue as fixed in range 558997:559001.

Detailed report: https://clusterfuzz.com/testcase?key=5377103391096832

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_msan_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  Lifecycle().StateAllowsTreeMutations() in document.cc
  blink::Document::UpdateStyleAndLayoutTreeIgnorePendingStylesheets
  blink::Document::UpdateStyleAndLayoutIgnorePendingStylesheetsForNode
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=535692:535694
Fixed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=558997:559001

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5377103391096832

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, May 16 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5377103391096832 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Status: Assigned (was: Verified)
Bulk edit: reopening CF issues likely closed incorrectly due to https://chromium.googlesource.com/chromium/src/+/cd3ebc4c69d7c01770f37f34aad623aa4ab2b128
Project Member

Comment 6 by ClusterFuzz, May 17 2018

ClusterFuzz has detected this issue as fixed in range 556036:556037.

Detailed report: https://clusterfuzz.com/testcase?key=5377103391096832

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_msan_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  Lifecycle().StateAllowsTreeMutations() in document.cc
  blink::Document::UpdateStyleAndLayoutTreeIgnorePendingStylesheets
  blink::Document::UpdateStyleAndLayoutIgnorePendingStylesheetsForNode
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=535692:535694
Fixed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=556036:556037

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5377103391096832

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Cc: kkaluri@chromium.org xidac...@chromium.org
 Issue 873578  has been merged into this issue.
Status: WontFix (was: Assigned)
 Issue 879925  has been merged into this issue.
Project Member

Comment 10 by ClusterFuzz, Sep 3

Labels: OS-Mac
Project Member

Comment 11 by ClusterFuzz, Sep 7

Labels: Needs-Feedback
ClusterFuzz testcase 6065642906845184 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Cc: pnangunoori@chromium.org
 Issue 884193  has been merged into this issue.
 Issue 885136  has been merged into this issue.
 Issue 887919  has been merged into this issue.
 Issue 889379  has been merged into this issue.
 Issue 889927  has been merged into this issue.

Sign in to add a comment